This Page Is Inserted by IFW Operations 
and is not a part of the Official Record 

BEST AVAILABLE IMAGES 



Defective images within this document are accurate representations of the 
original documents submitted by the applicant. 

Defects in the images may include (but are not limited to): 



BLACK BORDERS 

TEXT CUT OFF AT TOP, BOTTOM OR SIDES 
FADED TEXT 
ILLEGIBLE TEXT 
SKEWED/SLANTED IMAGES 
COLORED PHOTOS 

BLACK OR VERY BLACK AND WHITE DARK PHOTOS 
GRAY SCALE DOCUMENTS 



IMAGES ARE BEST AVAILABLE COPY. 



As rescanning documents will not correct images, 
please do not report the images to the 
Image Problems Mailbox. 



THIS PAGE BLkm mm) 



1^ 



cited in European Search 
Report of EPOA acc«.e 
Your Ref. : H^^vYT)- ;l<tg^ 



J 



Europalsches Patentamt 
European Patent Offic 
Offic europden des brevets 



(Jj) Publication number: 



HI 

0 546 701 A2 



EUROPEAN PATENT APPLICATION 



@ Application number: 92310549.8 
@ Date of filing: 19.11.92 



<£) lnt.C|5: G07F 7/10 



® Priority: 09.12.91 US 804780 


® 


Applicant: BRINK'S INCORPORATED 


20.12.91 US 811720 




Thorndale Circle P.O. Box 1225 


® Date of publication of application: 




Darlen Connecticut 06820-0473(US) 


® 




16.06.93 Bulletin 93/24 


Inventor: Heath, William D., Jr. 


® Designated Contracting States: 




2225 Cashtown Road 




Bremen, Georgia 30110(US) 


AT BE CH DE DK ES PR GB GR IE IT Li LU MC 






NL PT SE 








® 


Representative: Dealtry, Brian 






Eric Potter & Clarkson St Mary's Court St 






Mary's Gate 






Nottingham NG1 1LE (GB) 



@ Apparatus and method for controlled access to secured location. 
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@ A system for authorizing access to a secured 
location, such as the vault of an automated teller 
machine (ATM) or the coin box of a pay telephone, 
without a key or combination for the secured loca- 
tion, and without requiring a fixed communication 
link extending to the location. A service technician 
receives a encoded access message which identifies 
a present access code previously stored at the se- 
cured location, the personal identification number 
(PIN) of the technician, and the identification number 
of a portable terminal assigned to that technician. 
The technician manually enters the encoded access 
message and the proper PIN into the terminal, where 
the Identification number stored in the terminal and 
the manually-entered PIN are verified against the 
information encoded in the access message. If that 
information is authenticated, the technician then pro- 
ceeds to the secured location and connects the 
portable terminal to a processor at that location. The 
encoded access message is transferred from the 
terminal to the secured location, where the access 
code previously stored at that location is compared 
with information contained in the encoded access 
message. The technician must also re-enter the 
proper PIN at this time. Access is granted only if all 
information is verified by information in the encoded 
access message. If access is allowed, the access 
code at the secured location is replaced by a new 



access code contained in the encoded access mes- 
sage, and that new access code is stored for the 
next authorized access to the particular secured 
location. 
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Field of invention 

This invention relates in general to controlling 
access to a secured or locked location, and relates 
in particular to an apparatus and method for provid- 
ing controlled access by an identification number 
known only to an authorized person and by an 
access code known only at the secured location. 

Background of the Invention 

There are many applications where amounts of 
money are kept In unmanned facilities that are 
open to public access. For example, cash-operated 
devices such as vending machines and pay tele- 
phones are available to the public and accrue vary- 
ing"amounts"of~cash as they dispense goods or 
services to customers. These machines periodi- 
cally are serviced to remove the money and, in the 
case of vending machines, to replenish the supply 
of products. Persons authorized to service pay 
telephones or vending machines must carry keys 
permitting access to the coin box or other recepta- 
cle receiving money paid Into the machine. Pay 
telephone coin boxes are serviced by a collector 
who periodically visits each pay phone. The collec- 
tor unlocks an outer door to the phone using a key 
for that purpose, and then removes the coin box 
from within the phone and substitutes an empty 
coin box. If the collector is allowed to carry one or 
more master keys for servicing a number of tele- 
phones, the risk of loss by theft or misappropriation 
of a single key is apparent. On the other hand, 
requiring the collector to carry a separate key for 
each pay phone represents a significant Inconve- 
nience, particularly in areas such as airport termi- 
nals where large numbers of pay phones are lo- 
cated. Furthermore, the risk of loss through theft or 
misuse of individual key still exists. 

Automated teller machines (ATMs) are another 
example of machines containing cash and requiring 
periodic access for replenishing the cash supply or 
maintaining and repairing the machines. Because 
ATMs are capable of containing large amounts of 
money relative to most vending machines, they are 
more inviting targets for theft. For this reason, the 
cash within an ATM is contained within a small 
vault integral with the ATM and typically accessible 
only through a vault door having a combination 
lock, sometimes combined with a key access, for 
opening the vault door. Portions of the electronic 
controls for the ATM also may be located within 
the vault to prevent unauthorized cash dispensing 
by tampering with control circuits. Generally speak- 
ing, the cash within a locked ATM is secure from 
any unauthorized activity short of safecracking. 

The need for periodic access to the vault of an 
ATM machine to replenish the cash supply, or to 



service equipment within the vault, constitutes a 
weak link In ATM security. If vault access is avail- 
able only to technicians possessing the proper key 
or numerical combination to open the vault door. 

5 those technicians are vulnerable to being hijacked 
and forced to hand over the key or divulge the 
combination to open the vault. Furthermore, job 
turnover of ATM technicians makes it impractical to 
give each technician the combinations of ATM 

10 vaults, because of the need to reset those com- 
binations whenever the technician left the job. For 
the same reason, key-only access to ATM vaults 
presents a problem when the technician leaves the 
job, due to the risk that the technician may not 

75 return the keys or may make an unauthorized copy 
of the keys while employed. Further yet, security 
considerations rule against allowing any technician 
to carry master keys capable of unlocking the 
vaults in a number of different ATMs, due to the 

20 risk of great loss if such master keys were stolen 
or otherwise came into the wrong hands. 

Prior-art techniques are known for providing 
keyless access to ATMs or other machines con- 
taining significant amounts of cash. These tech- 

25 nlques generally require an electronic link between 
the machine and a central office, and an arrange- 
ment for unlocking the vault whenever the proper 
signal arrives from the central office. To avoid the 
cost of providing dedicated lines between the cen- 

30 tral office and a great number of ATMs, these prior- 
art techniques usually rely on the public telephone 
network and a modem associated with each ATM, 
in order to communicate between the central office 
and a selected ATM. While these techniques re- 

35 lieve the service technician of the need to carry 
either access keys or combinations for the ATM 
vaults, it still leaves the technician subject to being 
hijacked by robbers who will then coerce the tech- 
nician to request access from the central office. On 

40 a more sophisticated level, the use of conventional 
telephone lines for transmitting access signals to 
ATMs makes those signals subject to interception 
by wiretapping, leading to the fear that the access 
signals may be analyzed and then used by others 

45 for unauthorized access to ATM vaults. Moreover, 
the dial-up telephone line required for each ATM is 
an ongoing expense to the bank or other agency 
sponsoring the ATM. 

50 Summary of Invention 

Stated in general terms, a call for service or 
repair of an ATM or another secured device is 
reported to a service technician, along with a 
55 unique encoded access message generated for the 
particular occasion. The technician can receive this 
access message by telephone or radio dispatch, 
because the information contained therein is en- 
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crypted so as to conceal the information. This 
access message contains the personal itentification 
number (PIN) Identifying that particular technician, 
the serial number or other unique identifier of the 
particular portable terminal, present and future ac- 
cess codes for the secured device, and other in- 
formation appropriate for a particular application, all 
as encrypted in the encoded access message. The 
technician carries a portable terminal and enters 
the access message into that terminal along with a 
PIN. and the portable terminal verifies access mes- 
sage was entered in the correct terminal and that 
the proper PIN was used. The technician then 
travels to the location of the ATM or other device 
requiring service. At that location, the technician 
connects the portable terminal to the secured de- 
vice and once again enters the PIN into the termi- 
nal, where that number again is verified against the 
access code previously contained in the encoded 
access message. This double verification of the 
technician's PIN thwarts unauthorized access in a 
situation where the technician is hijacked after re- 
ceiving a service call from the dispatcher and then 
entering the proper PIN into the portable terminal 
for self-authentication. With the portable terminal 
connected to the secured device, the encoded 
message is sent to the device where a computer 
checks for the presence of correct information 
identifying the device and authenticating the ac- 
cess being requested, and allows access to the 
vault only if that correct information is present. 

Because the PIN assigned to the particular 
technician is among the information contained in 
the encoded access message initially furnished to 
the technician, the present system accommodates 
the departure of a technician simply by retiring that 
person's PIN number from further use and assign- 
ing new numbers for new technicians. Any un- 
authorized interception of an access message 
thereafter by a former technician will fall, even if 
intercepted by someone possessing a portable ter- 
minal obtained by theft or fraud, because the serial 
number of that terminal will not match the cor- 
responding number in the encoded access mes- 
sage and because that person does not know the 
new PIN for use by someone else and encoded 
into the access message. 

Stated somewhat more particularly, the en- 
coded access message transmitted to the techni- 
cian according to the present invention includes a 
present access code for gaining access to the 
secured location at the present time, in addition to 
the PIN for the technician authorized for that ac- 
cess. This present access code must correspond 
to an access code previously stored at the secured 
location, or else the system w|ll deny the present 
attempt to gain access to the sefe^ured location. The 
encoded access message also contains a new ac- 
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cess code intended for future use by that particular 
secured location. If the PIN ntered by the techni- 
cian matches the PIN encoded in the access mes- 
sage and if the present access code within that 

5 message matches the access code previously 
stored at the secured location, then access is 
granted and that present access code is erased 
and replaced by the new access code contained in 
the encoded message. This new access code re- 

10 mains stored at the secured location and becomes 
the authorized access code for use the next time 
access to that location is sought. In this manner, 
each access code is used only one time and 
anyone attempting to create an encoded access 

75 message for a particular location must have 
present knowledge not only of that location, the 
authorized PIN for a particular technician, and the 
serial number of the particular portable terminal 
authorized for that technician, but must also know 

20 the access code previously stored at that secured 
location. Without this specific Information, and oth- 
er information as may be appropriate and as de- 
scribed further herein, an attempt to counterfeit an 
encoded access message will fail. Each present 

25 access code preferably is unique to a particular 
secured location and may be based on a 
randomly-generated number, so that the likelihood 
of duplicating that number by chance becomes so 
low as to be negligible in practice. The ATM can 

30 maintain a historical file of all attempts to access 
the vault, whether granted or disallowed. If a low 
occurs, one can consult the historical file for 
preloss activity. This information may also predict 
problems arising from repeated attempts to access 

35 the vault. 

Accordingly, it is a object of the present inven- 
tion to provide an improved apparatus and method 
for controlling access to a secured location. 

It is another object of the present invention to 

40 provide an improved apparatus and method for 
controlled access to automated teller 

It is a further object of the present invention to 
provide the capability of selective access to a 
secured location without requiring a telephone line 

45 or other data link between that location and a 
central office. 

It is still another object of the present invention 
to provide an apparatus and method for authorized 
access to a locked location without requiring either 

60 a key or the combination for a lock, or by requiring 
a level of security in addition thereto. 

It is yet another object of the present invention 
to provide an improved apparatus and method for 
selective access to the coin box of a pay telephone 

55 or the like. 

Other objects and advantages of the present 
invention will become more readily apparent from 
the following disclosure of a preferred embodiment. 

3 
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Brief DescrlptI n of Drawings 

Fig. 1 is a schematic view illustrating the flow 
of information required for gaining access to a 
secured location according to a first preferred em- 
bodiment of the present invention. 

Fig. 2 represents the information contained in 
an encoded access message according to the first 
embodiment. 

Figs. 3 and 3A are pictorial views illustrating a 
portable terminal used in the first embodiment. 

Fig. 4 Is a block diagram illustrating compo- 
nents of the portable terminal and interfacing com- 
ponents of an ATM, in the first embodiment. 

Fig. 5 is a perspective view showing the ac- 
cess latch mechanism according to the preferred 
embodiment. 

Fig. 6 is a fragmentary elevation view of the 
latch mechanism shown in Fig. 5. 

Fig. 7 is a flow chart illustrating operational 
steps in the method of the first embodiment. 

Fig. 8 is a block diagram of apparatus for 
controlled access to the coin box of a pay tele- 
phone according to a second preferred embodi- 
ment of the present invention. 

Rg. 8A is a schematic diagram of a pay tele- 
phone circuit according to the second embodiment. 

Fig. 9 is a flow chart illustrating operational 
steps of the second embodiment. 

Fig. 10 is a block diagram of a pay telephone 
coin box access apparatus according to a third 
preferred embodiment of the invention. 

Fig. 11 is a flow chart illustrating operational 
steps of the third embodiment. 

Fig. 11A is a flow chart illustrating operational 
steps of the bar-code scanning option disclosed 
with regard to the second and third embodiments. 

Detailed Description of Preferred Embodiment 

Fig. 1 shows a functional outline of a secured 
access system according to a preferred embodi- 
ment of the present invention. This secured access 
system includes at least one secured location 10, 
such as an ATM or other apparatus having a vault 
or other secured enclosure normally kept locked 
and inaccessible to unauthorized persons. In actual 
practice, systems utilizing the present invention are 
associated with a number of separate secured loca- 
tions, such as the ATMs belonging to a particular 
bank or located in a particular area. A number of 
these secured locations 10 are serviced by one or 
more technicians 11 in response to instructions 
received from a dispatcher 12 at a central location 
Each technician 11 carries a portable computer 
terminal 13 which may be a conventional hand-held 
terminal programmed to function as pointed out 
below in greater detail. 
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The dispatcher 12 receives information as in- 
dicated by the line 16, concerning problems with a 
secured location 10. These reports may be relayed 
from the bank or other institution that operates or 

5 sponsors the secured locations, or alternatively 
may come directly from the secured locations 
themselves by way of telephone links reporting a 
problem at the secured location. Upon receiving a 
problem report concerning a particular secured lo- 

10 cation 10, the dispatcher 12 obtains from the dis- 
patch computer 17 an encoded access message 
that a selected technician 11 must use to gain 
access to that particular secured location. This 
access message contains various information as 

75 pointed out below in greater detail, including in- 
formation identifying the present access code pre- 
viously stored at that location, the PIN of the par- 
ticular technician 1 1 selected by the dispatcher to 
visit the secured location, and the serial number of 

20 the portable terminal 13 assigned to that particular 
technician. It should be understood that the fore- 
going information preferably is contained in a 
database maintained at the dispatch computer 17. 
The dispatch computer 17, at the request of the 

25 dispatcher 12, generates a number containing the 
foregoing access information in encoded form. This 
number thus becomes an encoded access mes- 
sage which the dispatcher 12 can send to the 
technician 11 over an open link 18, such as a 

30 telephone line or radio dispatch communication, 
without concern that unauthorized interception of 
the encoded access message will yield any useful 
information to anyone lacking the proper terminal 
13 and the PIN of the technician. 

35 The technician 1 1 . upon learning from the dis- 

patcher 12 that a particular secured location 10 
requires attention and receiving the encoded ac- 
cess message for that particular job, manually en- 
ters that access message into the portable terminal 

40 13. The technician also enters his or her assigned 
PIN into the portable terminal 13. The portable 
terminal compares its own serial number or other 
internal identification number with the known serial 
number of the terminal assigned to the particular 

45 technician 11, as based on information within the 
database of the dispatch computer 17. to confirm 
that the access information was entered into the 
proper portable terminal. The manually-entered PIN 
also is compared with the PIN encoded in the 

50 manually-entered access message to make certain 
those PINs match; the portable terminal preferably 
is programmed to erase the entire encoded access 
message at this time, if the PIN manually entered 
by the technician does not match the PIN informa- 

55 tion contained within the encoded access message 
received from the dispatcher 18. This erasure of 
the access message aborts the access procedure 
without recourse, so that a hijacked terminal 13 

4 
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cannot thereafter be disassembled and the interna) 
nnemory electronically read by a technically-sophis- 
ticated thief in an effort to retrieve the encoded 
access nnessage from the portable terminal. 

After the portable terminal 13 verifies it is the 
proper terminal indicated in the encoded access 
message and that the proper PIN was entered, the 
technician then travels with the terminal 13 to the 
secured location 10. At that location, the technician 
connects the portable terminal 13 to the ATM or 
other apparatus at the secured location, whereupon 
the portable terminal transfers to the secured loca- 
tion the encoded access message that the techni- 
cian previously received from the dispatcher and 
entered into the portable terminal. At this time the 
technician must again enter his PIN into the porta- 
ble terminal, where that number again must match 
the PIN encoded in the access message. The 
computer within the secured location also com- 
pares the serial number of the portable terminal 13 
with the terminal serial number within the encoded 
message, to confirm that the terminal connected to 
the secured location is in fact the terminal assigned 
to the particular technician based on information 
within the encoded access message. 

As a further check on the integrity of the en- 
coded access message and the authenticity of the 
access being sought, a "present access code" 
previously stored at the secured location 10 is 
compared with a present access code within the 
encoded access message and obtained from the 
database of the dispatch computer 17. If those 
present access codes match, the vault door or 
other access port at the secured location is re- 
leased, allowing access by the technician 11 for 
service or maintenance. The secured location at 
this time may return Information to the still-con- 
nected portable terminal 13 indicating that access 
was grated, together with the date and time this 
access began and ended. The technician 11 can 
later upload that access-related information from 
the portable terminal 13 to the dispatch computer 
17, thereby providing the dispatcher 12 with an 
historical record of telling when and by whom var- 
ious secured locations 10 were accessed. 

If the incorrect PIN is entered Into the portable 
terminal 13 when connected to the secured loca- 
tion 10, an alarm signal is optionally provided along 
the line 21 to an alarm 22. This alarm 22 preferably 
is an off-site alarm located remotely from the se- 
cured location 10, with the alarm transmitted along 
a telephone line or radio link represented by the 
line 21 to alert the police or other authorities about 
a possible unauthorized attempt to gain entry, to 
protect the safety of a hijacked technician forcibly 
detained at the secured location 10. 

The Information contained in the encoded ac- 
cess message used with the preferred embodiment 



BNSDOCID: <EP_0546701A2_L> 



of the present invention is shown in Fig. 2. That 
information includes the PIN 26 identifying the par- 
ticular technician 11 dispatched for a service call to 
an ATM, and the serial number 27 of the portabi 

5 terminal 13 assigned to that technician. The en- 
coded access message also contains the present 
access code 28 corresponding to an access cod 
previously stored at the ATM In question, and th 
"next access code" 29 that replaces the present 

10 access code at the ATM upon successful authori- 
zation of the present access. Although not included 
in the particular access message of the preferred 
embodiment, the access message can include oth- 
er information relevant to security, such as an ATM 

75 code identifying the particular ATM to which th 
technician 11 has been dispatched, and the date 
and time of this particular service request. A check 
sum digit 32 may also be Incorporated into the 
information contained In the encoded access mes- 

20 sage, as is known to thou skilled in the art. Th 
information contained in the access message as 
illustrated in Fig. 2 is encoded by appropriate 
known public encryption algorithms such as the 
Data Encryption Standard (DES), which is widely 

25 documented and has been accepted by the bank- 
ing Industry for electronic information exchange. 
Encryption and decryption of information as used 
herein thus is within the skill of the art. The actual 
encoded access message delivered by the dls- 

30 patcher 12 to the technician 11 thus consists, for 
example, of a 12-digit string having no humanly- 
perceptable relation to the information depicted in 
Fig. 2. That 12-dlgit string is subsequently decoded 
by software within the portable terminal 13 and 

35 within the secured location 10 after the encoded 
access message is transferred to that location. 

A portable terminal 13 used in the preferred 
embodiment of the present invention is shown in 
Fig. 3, and the major operational components of 

40 that terminal are depicted in Fig. 4. The portable 
terminal 13 includes a keyboard 36 connected to a 
central processing unit (CPU) 37. which in turn 
drives a display 38. A memory 39 Is connected to 
the CPU and contains stored programming to per- 

45 form the operational steps as described below. As 
seen In Figs. 3 and 3A, the display 38 comprises a 
flat LCD panel which in that figure displays an 
alphanumeric keypad and also displays the com- 
mand "Enter PIN:" 40 at the upper-left corner of 

50 the panel. The electrical contacts of the keyboard 
36 are situated beneath the flat panel display 38, 
which is sufficiently flexible or otherwise responsive 
to the finger pressure of a person entering an 
alpha/numeric PIN and then pressing the "Enter" 

55 key 41 appearing at the lower-right corner of the 
display 38 in Fig. 3. 

Portable terminals suitable for use with the 
present invention are obtainable from various sour- 

5 
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ces. The programming of such terminals is well 
known to those of ordinary skill of the art and need 
not be further described herein. The programming 
code to perform the steps described herein prefer- 
ably is stored in battery-powered RAM within the 
terminal, so that the programming is electronically 
erasable in the event of tampering with the termi- 
nal. The alpha/numeric keyboard and menu display 
39 generated on the display 38 of the portable 
terminal 13, as shown in Fig. 3, is selectively 
replaceable by a programmed message display, 
such as the message "ADMISSION GRANTED" 
shown on the display 38 in Fig, 3A. 

A cable 44 extends from the portable terminal 
13 for connecting that terminal to a RS-232 port at 
the ATM or other secured location 10, as depicted 
in Fig. 4.- The cable 44 provides an interface for 
transferring data between the CPU 37 of the porta- 
ble terminal 1 3 and the CPU 46 forming part of the 
present apparatus at the secured location 10. al- 
though those skilled in the art will understand that 
other data-transfer techniques can be substituted 
for the cable. That secured location 10 further 
includes a memory 47 associated with the CPU in 
the conventional manner. An output from the CPU 
46 is connected via the signal line 48 to selectably 
drive a solenoid latch 49 when admission to the 
secured location 10 is granted. The CPU 46 at the 
secured location 10 optionally provides a signal on 
the line 21 leading to the silent alarm which, if 
present as previously mentioned, can indicate an 
unauthorized access such as entry of the wrong 
PIN or deliberate entry of a PIN previously chosen 
to alert others that an emergency exits at the 
secured location. 

Figs. 5 and 6 show the inside of a vault door 
52 modified according to the present invention. The 
vault door 52 is of a kind typically used in ATMs 
and is shown opened in Fig. 5. This vault door 
includes a locking bolt 55 in the form of heavy 
steel plate extending parallel to the open edge 54 
of the vault door. The locking bolt 55 slides within 
the fixed sleeve 53 along one side thereof adjacent 
the door edge 54. The locking bolt 55 thus is 
supported to move laterally from its unlocked posi- 
tion shown in Fig. 5, leftward as indicated by the 
arrow 56 to a locked position in which the locking 
bolt engages mating structure (not shown) adjacent 
the open portal of the vault to retain the vault door 
shut in the portal. 

The locking bolt 55 is moved between open 
and closed positions by rotating the conventional 
handle 59 located on the front side of the door 52. 
The handle 59 rotates the lever 60 on the inside of 
the vault door, imparting lateral movement to the 
locking bolt 55 through a pin and link connection to 
the lever. The combination lock and/or key lock 
conventionally used with the handle 59 are omitted 



BNSDOCID: <EP_0546701A2_L> 



herein for clarity. 

A bar 63 is attached at one end to the locking 
bolt 55 and extends perpendicular to that locking 
bolt, as best seen in Fig. 6. The bar 63 thus moves 

5 with the locking bolt 55 as that bolt is moved 
laterally by operation of the handle 59. The sole- 
noid latch 49 is mounted on the inside of the door 
52 at one side of the bar 63, so that the solenoid 
armature 64 extends toward the bar. A spring 65 is 

10 concentric with the solenoid armature 64 and bi- 
ases that armature in a direction toward the bar 63. 

An opening 68 sized to receive the free end of 
the solenoid armature 64 extends through the bar 
63. This opening 68 is positioned on the bar 63 in 

75 relation to the armature 64 so that the opening 
becomes aligned with the armature only when the 
locking bolt 55 of the vault door 52 is moved 
leftwardly, as indicated by the arrow 56 in Fig. 5, to 
the locked position. In that locked position, the 

20 spring 65 forces the solenoid armature 64 upwardly 
to enter the opening 68 and lock the bar 63 in 
position as shown in Fig. 6. This engagement of 
the bar 63 by the bolt 64 thus effectively prevents 
withdrawing the locking bolt 55 from its locked 

25 position by movement of the handle 59, unless the 
solenoid 49 is energized to withdraw the armature 
from engagement with the bar 63. 

The operation of the preferred embodiment is 
now described with regard to the flowchart. Fig. 7, 

30 representing the functional steps programmed to 
accomplish the method. The depicted process as- 
sumes that access to a particular ATM has been 
requested. As previously mentioned, this service 
request commences according to the disclosed 

35 embodiment when a dispatcher learns that a par- 
ticular ATM requires maintenance or service. The 
dispatcher selects a particular technician for the 
job, and then enters the identification of the ATM 
and that technician into the dispatch computer 17 

40 (Fig. 1) which obtains from its database the re- 
quired information including the PIN of the selected 
technician, the serial number of the portable termi- 
nal assigned to that technician, the present access 
code previously stored in the ATM, and other in- 

45 formation as shown in Fig. 2. The computer then 
encrypts that information, producing a 12-digit en- 
coded access message in the present embodiment 
a shown at 70 in Fig. 7. The dispatcher then tells 
the technician the location of the ATM requiring 

50 service and announces the 12-digit encoded ac- 
cess message. 

Upon receiving this message, the technician 
manually enters the 12-digit access message into 
the portable terminal 13 using the keyboard 36 for 

55 that purpose, as indicated at step 71 in Fig. 7. The 
portable terminal 13 decrypts the encoded access 
message as shown at 72 and then compares the 
terminal serial number 27 (Fig. 2) contained in the 

6 
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access message with the actual serial number pro- 
grammed into that terminal, as shown at 73 In Fig. 
7. If those serial numbers do not match, the termi- 
nal 13 aborts the access attempt at that time and 
displays an appropriate message for the technician 
on the display 38 of the portable terminal. This 
aborted access safeguards against access attempts 
using a terminal obtained by theft or remaining in 
the possession of a former technician no longer 
authorized for access to an ATM. 

If the terminal serial number matches in step 
73. the terminal then prompts the technician as 
shown at 40, Fig. 3, to enter his PIN into the 
terminal. This step is shown at 74 in Fig. 7. The 
terminal then compares the manually-entered PIN 
_with-the technician's authorized PIN 26 (Fig. 2) 
contained in the encoded access message. If those 
PINs don't match, the terminal prompts the techni- 
cian to re-enter the PIN at the keyboard. However, 
if these repeated attempts to enter the technician's 
PIN produce no match, the terminal 13 aborts the 
access attempt and erases the entire encoded ac- 
cess message as shown at 75 in Fig. 7. In this 
way, anyone who steals or hijacks a technician's 
portable terminal 13 and then intercepts instruc- 
tions from the dispatcher, including the 12-digit 
access message, is thwarted in repeated attempts 
to guess the proper PIN. Moreover, in that situation 
the terminal effectively forgets the 12-digit number 
previously keyed into it making it impossible to 
retrieve that number by disassembling the terminal 
and examining the logic states of the memory or 
CPU within. 

Once the technician enters the correct PIN at 
step 76, the terminal 13 displays a message ac- 
knowledging that entry and then erases the 
manually-entered PIN from its memory. This era- 
sure of the PIN, shown at 77, provides another 
level of security, as that PIN cannot be determined 
by electronic inspection of a terminal hijacked from 
a technician after entry of the proper PIN. The 
terminal then re-encrypts the access message us- 
ing a second encryption algorithm different from 
the first such algorithm for an added level of secu- 
rity, as shown at step 78 in Fig. 7. 

After the technician has entered the proper PIN 
into the terminal 13 as discussed above, the techni- 
cian travels to the location of the ATM and con- 
nects the terminal 13 to the CPU 46 of the ATM, 
using the cable 44 for that purpose as Illustrated in 
Fig. 4. The technician then reenters the PIN as 
shown at 79 into the portable terminal, which must 
reconform that the proper PIN is presented as 
shown at 80. If the PIN matches that in the access 
message, the re-encrypted access message is 
transferred as shown at 81 to the CPU 46 within 
the ATM, where the access message is decrypted 
by that CPU. At this time, the present access code 
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28, contained within the access message, is com- 
pared at 82 with the present access code pre- 
viously stored in memory 47 at the ATM. If these 
access codes don't match, the attempted access is 

5 aborted at that point as indicated at 83 in Fig. 7. 

If the proper access code and the proper ATM 
are confirmed, the PIN on the keyboard 36. as 
shown at step 84. If that PIN previously re-entered 
at step 79 matches the alarm PIN contained within 

10 the encoded access message, the system per- 
forms certain alarm functions as previously dis- 
cussed. Otherwise, access to the ATM is allowed 
as indicated at 85, Fig. 7. The CPU 46 at the ATM 
accomplishes this access by sending a signal 

75 along line 48 to activate the solenoid 49, Figs 5 
-and 6, withdrawing the armature 64 of the solenoid 
from the opening 68 in the bar 63 connected to the 
locking bolt 55 of the vault door. The technician 
can then rotate the handle 59 to withdraw the 

20 locking bolt 55 from engagement with its recepta- 
cle in the vault, thereby unlocking the door for 
access to the vault. 

After access is allowed at step 85, the present 
access code previously stored within memory 47 at 

25 the ATM is erased as shown at 89 and replaced 
with the next access code 29 contained in the 
encoded access message. This next access code 
remains in memory 47 and in effect becomes a 
new "present access code" for this particular ATM. 

30 After the access code is updated at the ATM. both 
access codes are erased in the portable terminal 
as shown at 90. As previously mentioned, the next 
access code 27 also is stored at the dispatch 
computer 1 7. The next time access to this particu- 

36 lar ATM is required, the dispatch computer 17 will 
generate a new encoded access message in which 
the current "next access code" 29 will become the 
"present access code" for that new access mes- 
sage. This updating of the access message stored 

40 at the ATM or other secured location 10 is a 
significant aspect of the present invention, because 
each authorized access to the ATM automatically 
updates the access code required for the next 
access to that ATM. No subsequent access to the 

45 ATM is possible without that updated access code, 
which is known only in memory 47 within the 
particular ATM and at the dispatch computer 17. 
The CPU 46 associated with the ATM 10 initially 
includes a default access code which is used (and 

50 then replaced) for the initial access to the vault. 
This default access code may be set by jumper 
connectors attached to a circuit board and removed 
when the system is initialized. The CPU 46 and 
memory 47 preferably have a battery backup pow- 

55 er source to prevent memory loss during power 
outages. 

Once access to the ATM is completed, in- 
formation concerning that access is transferred to 

7 
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the terminal 13 from the CPU 46 associated with 
the ATM. This access information can Include ver- 
ification that access was allowed, the date and time 
of such allowance, and the time that the access 
was terminated, i.e., that the technician closed and 
relocked the vault door 52. The technician periodi- 
cally uploads this access information from the por- 
table terminal 13 to the dispatch computer 17, 
either by directly connecting the portable terminal 
to the dispatch computer or by dial-in telephone 
link as appropriate to the particular work patterns of 
the system. This information allows the dispatcher 
to maintain a database showing the workload of 
each technician, including the response time for 
each service call and the time elapsed while the 
vault door of each ATM remained open. As men- 
tioned above, the access information also can in- 
clude the date, time, and disposition of all attempts 
to access, the PINs and terminal serial numbers 
employed with those attempts, and other relevant 
data possibly indicating unauthorized activity at that 
location. 

Modifications to the program access steps 
shown in Fig. 7 are permissible. For example, after 
a technician has gained access to the vault, he 
may find that a particular replacement part or ser- 
vice tool is required from the service vehicle. Secu- 
rity procedure requires that the technician must not 
leave the open vault unattended, but locking the 
vault door otherwise will require reinitiating the ac- 
cess authorization procedure shown in Fig. 7. How- 
ever, once access has been allowed as shown at 
step 85 In that procedure, the program can be 
modified to allow the technician to close and relock 
the vault door but leave the terminal 13 connected 
to the ATM white obtaining the desired component 
from the service vehicle. Upon retuning to the 
ATM, the technician merely re-enters the PIN Into 
the terminal 13, whereupon the solenoid latch 49 is 
again activated to unlock the vault door if the 
proper PIN was entered. 

Figs 8, 8A, and 9 show an embodiment in- 
tended for use In controlling access to the coin 
boxes of pay telephones. As shown in Figs. 8 and 
8A, a typical pay telephone 89 includes a ringer 91 
connected in parallel across the sides 92a. 92b of 
the telephone line 92 connecting the pay telephone 
to the telephone central office In the conventional 
manner. However, the ringer circuit Is modified 
according to the present invention so that the side 
of ringer 91 connected to the line 92a passes 
through the switch 93 having a default condition 
connecting line 92a to the ringer, as shown In Fig. 
8A. Actuating the switch 93 in response to the 
access circuit 97, as explained below, removes the 
line 92a from the ringer and instead connects that 
line to one side of the solenoid lock 94. The other 
side of the solenoid lock 94 is connected to the line 
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92b. Thus, when the switch 93 is diverted from its 
default position shown in Fig. 8, ringing current 
from the central office Is received by the solenoid 
lock 94 instead of the ringer 91 . 

5 The switch 93 is under operational control of 

the access circuit 97 connected across the tele- 
phone lines 92a and 92b, which extend beyond the 
access circuit for connection with the conventional 
dialing, speech, and coin-control equipment for- 

10 ming part of the pay telephone. The access circuit 
97, which in practice is disposed on a circuit board 
mounted within the pay telephone, contains a pro- 
cessor programmed to store a predetermined ac- 
cess code, to compare that stored access code 

75 with a present access code received over the tele- 
phone line 92a, 92b, and to temporarily set the 
switch 93 so that ringing current from the tele- 
phone central office is temporarily diverted from 
the ringer 91 to the solenoid 94. The processor 

20 within the pay telephone also decrypts the access 
Information received from the portable terminal and 
the central office, if that information is initially en- 
crypted. With the switch 93 thus set by the access 
circuit 97, the solenoid lock 94 is activated by 

25 ringing current from the central office the next time 
this particular pay phone is called. The solenoid 
lock 94 thus unlocks the outer door 130 enclosing 
the coin box 131 of the phone, enabling the collec- 
tor to service the coin box without using a key. 

30 The operational program used in connection 

with the present pay-telephone access system is 
shown in Fig. 9. It should be understood that a 
collector servicing pay phones equipped according 
to the present invention carries a portable terminal 

35 96 equivalent to the terminal 13 described 
hereinabove. However, portable terminals for pay- 
phone access preferably include or are modified to 
include an acoustic coupler for establishing audio 
communication with the existing handset 98 of the 

40 pay telephone. Before the collector sets out on a 
route to service particular phones on a given day, 
the telephone numbers of those phones are en- 
tered into a dispatch computer along with the PIN 
assigned to the particular collector, the serial num- 

45 ber of the portable terminal carried by that collec- 
tor, and the particular date for collection from those 
phones. That information is downloaded to the por- 
table terminal as shown at step 101 In Fig. 9, and 
the collector then travels to the first phone for that 

50 day. 

As the collector visits each pay phone chosen 
for collection on a particular day, the collector 
connects the handset of that phone to the portable 
terminal 96 as shown at 102 in Fig. 9. and then 
55 dials the telephone number for connection to the 
dispatch computer as shown at 103. It will be 
evident that the telephone number of the dispatch 
computer advantageously is programmed into the 
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collector's portable terminal, which can outpuise 
DTMF signals acoustically coupled to the tele- 
phone handset of the pay phone. 

Once telephone communication is established 
between the particular pay phone and the dispatch 
computer, the collector enters the assigned PIN 
into the portable terminal as shown at 104. That 
PIN and the terminal serial number or identification 
internally programmed within the terminal are 
transmitted to the dispatch computer as shown at 
105. That number is transmitted to the dispatcher. 
The serial number of the portable terminal and the 
PIN of the collector are compared with information 
in the dispatch database for verification on that 
particular date, as shown at 106 and 107, and the 
attempted- access to the coin box of the pay phone 
is aborted if verification of that information is not 
forthcoming. 

Once the collector's PIN and the terminal Iden- 
tification are verified, the dispatch computer trans- 
mits a coded access message over the telephone 
line connected to the pay phone, as shown at 108. 
This message is received by the access circuit 97, 
Fig. 8, and takes the form of DTMF audio pulses 
for telephone systems presently existing. 

The access circuit 97 within the pay phone 
comprises a central processing unit (GPU) and 
memory similar to the CPU 46 and memory 47 
associated with the ATM 10 in the embodiment 
previously described. This access circuit is pro- 
grammed to decrypt the access message. If that 
message was originally transmitted In encrypted 
form, and compare the "present access code" of 
that message with the corresponding code pre- 
viously stored within the access circuit. This step is 
shown at 110 In Fig 9. If the access circuit 97 
verifies receipt of the proper access code, that 
circuit sets the switch 93 from its default position 
shown in Fig. 8A, to the position connecting the 
solenoid latch 94 to both sides of the telephone 
line 92a, 92b. At this time, the dispatch computer 
hangs up as shown at 111 in Fig. 9, breaking the 
telephone connection to the pay telephone. 

The dispatch computer next immediately re- 
dlals that pay phone as shown at 112. In response 
to this redialing, the telephone company central 
office sends ringing current on the lines 92a and 
92b and this ringing current now passes through 
the solenoid latch 94 instead of the ringer 91 . If the 
callback fails to occur in a predetermined time after 
hangup 111, the attempted access aborts as shown 
at 113 and the switch 93 restores the ringer 91 to 
default mode connected across the telephone lines. 
The ringing current thus operates the solenoid latch 
to unlock the door 130 to the coin box, as shown at 
111 allowing the collector to remove the full coin 
box 131 and replace it with an empty one In 
accordance with established practice. The access 
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circuit 97 at this time erases the "present access 
code" previously stored therein, and receives and 
stores a "next access code" contained in the ac- 
cess message previously received from the dis- 

6 patch computer, as shown at 116. The access 
circuit 97 also restores the switch 93 to its default 
state, reconnecting the ringer 91 across the tele- 
phone lines 92a, 92b to receive ring current the 
next time this pay phone receives a call. 

10 The pay phone access system described here- 

in allows a collector to access the coin boxes of 
pay phones without carrying any individual keys or 
master key for the telephones, relying only on the 
portable terminal and information previously stored 

76 at the dispatch computer. However, coin-box ac- 

cess with the present system is possible only if the 

present access code stored in the access circuit of 
the telephone matches the present access code 
received from the dispatch computer, making it 

20 virtually impossible for an enterprising thief to pro- 
gram a personal computer to emulate the functions 
of the portable terminal carried by the collector. 
Moreover, telephone access is obtained only after 
active participation from the dispatch computer, 

25 namely, redialing the pay phone within a short time 
after authorization and initial hang up. 

Figs. 10 and 11 show an alternative embodi- 
ment for controlled access to the coin boxes of pay 
telephones. Moreover, and unlike the pay-tele- 

30 phone embodiment described with reference to 
Figs. 8, 8A, and 9. this alternative embodiment can 
access the coin box of a pay telephone when the 
telephone line is inoperative or not connected to 
the pay telephone. The embodiment shown in Fig. 

35 10 does not require the pay phone to originate or 
receive any calls, and does not add to the traffic 
load on the telephone system during peek-load 
daytime hours when pay phone collections usually 
take place. 

40 Turning first to Fig. 10, the pay telephone 127 

is modified to contain an access circuit 123 con- 
nected to drive a solenoid lock 129 which, when 
energized, unlocks the door 130 and allows access 
to the removable coin box 131 contained within the 

45 pay telephone. Unlike the access circuit 97 in the 
embodiment of Fig. 8, the access circuit 128 does 
not operate a switch to divert ringing current to the 
solenoid lock. However, the access circuit 128 per- 
forms many security functions similar to those of 

50 the preceding embodiments, as Is described below, 
and that access circuit selectively furnishes the 
solenoid 129 with operating power obtained from 
the portable terminal 135 temporarily connected to 
the pay telephone 127 by a collector. The conven- 

55 tional pay phone 127 thus requires modification to 
add the access circuit 128. the solenoid lock 129, 
and a port 136 for establishing data and power 
transfer between the access circuit 128 and the 
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portable terminal 135. The electrical power re- 
quired to drive the solenoid lock 129 preferably is 
obtained from the battery pack associated with the 
terminal 135; the power required for momentary 
actuation of the solenoid lock required to unlock 
the door 130 is well within the capacity of battery 
packs used on conventional portable terminals, and 
that momentary power requirement does not sig- 
nificantly reduce the useful lifetime of the battery 
pack between charges. 

Operation of the embodiment as thus far de- 
scribed with respect to Fig. 10 is now described 
with reference to Fig. 11. As with the portable 
terminal 96 used for pay-telephone access in the 
embodiment of Fig. 9. the portable terminal 135 
receives information from a dispatch computer or 
host computer concerning the telephone numbers 
and locations of pay telephones scheduled for col- 
lection on a given day. The identification number of 
the authorized portable terminal, the present ac- 
c ss code and a future access code for each of 
those pay telephones, along with the PIN assigned 
to the particular collector, also are included in the 
Information downloaded to the portable terminal 
135, This information can be downloaded to the 
portable terminal by modern and telephone link to 
the host computer, as appearing at step 137 in Fig. 
11. 

The collector then travels to a pay telephone 
set for collection on the particular day and, as 
shown at 138 in Fig. 11, connects the portable 
terminal 135 to the port 136 installed at that pay 
telephone. The collector next enters the known PIN 
into the terminal 135 as shown at 139 in Fig. 11, 
where the terminal must confirm that PIN with the 
encrypted information previously downloaded to 
the terminal before proceeding further along the 
access steps. 

If the portable terminal 135 confirms the iden- 
tity of the PIN entered by the collector, the terminal 
erases that manually-entered PIN as shown at 140 
and then transfers to the pay telephone the en- 
coded access message previously downloaded for 
that particular telephone. That access message is 
decrypted by a decryption algorithm stored within 
the access circuit 128, as shown at step 140 in Fig. 
11. The decrypted access message includes the 
telephone number of that particular pay telephone, 
and that information is compared with the actual 
number assigned to that telephone and stored in 
the access circuit 128 to verify that the portable 
terminal is connected to the correct telephone. This 
verification is shown at 141 in Fig. 11, If the correct 
telephone is indicated, the access circuit 126 com- 
pares the present access code decrypted from the 
access message with the present access code 
previously stored within the access circuit of that 
telephone. If these access codes match as shown 



at 142, the access circuit 128 closes a connection 
between the portable terminal 135 and the solenoid 
lock 129, actuating that lock to unlock the door 
135. The collector now opens the door and gains 

6 access to the removable coin box 131 within the 
pay telephone. 

With access thus authorized at the particular 
pay telephone, the access circuit replaces the 
present access code in the access circuit 128 with 

10 a new access code contained in the access mes- 
sage downloaded from the terminal, and sends to 
the portable terminal 135 selected Information 
about the particular access. This information can 
include the date and time access was granted, that 

75 information being associated within the portable 
terminal 135 with the phone number of the particu- 
lar pay telephone being serviced and the PIN iden- 
tifying the collector. This access information is later 
uploaded from the portable terminal 135 to the host 

20 computer at the dispatch location or elsewhere, as 
shown at 144 in Fig. 11. The collector, after remov- 
ing the full coin box-and replacing it with an empty 
receptacle, then disconnects the portable terminal 
135 from the pay telephone and travels to another 

25 pay telephone scheduled for service on that date. 

It will thus be seen that the pay-telephone 
access system described with regard to Figs. 10 
and 11 permits selective and controlled access to 
the telephone coin box without placing or receiving 

30 any telephone message at the pay telephone, and 
without requiring power from an incoming call or 
otherwise from the telephone company central of- 
fice to actuate the unlocking mechanism within the 
telephone. The present embodiment of controlled- 

35 access system thus does not add to the traffic load 
on the telephone switching system, and increases 
the speed of access by eliminating the time re- 
quired for placing the initial call and then awaiting 
the call-back associated with the embodiment of 

40 Figs. 8 and 9. 

Referring once again to Figs. 8 and 10, it is 
seen that each of the portable terminals 96 and 
135 is optionally equipped with a bar code scanner 
148 which operates to read a bar code label 150 

45 on the empty coin box 149 as well as a similar 
label on the full coin box 131 within the pay tele- 
phone. Such portable terminals including a bar 
code scanner are known in the art and are com- 
mercially available, one example being the Dense 

50 Model BHT-2061 terminal made by NippsonDenso 
Company. When used with the embodiment shown 
in Fig. 10, this terminal is equipped with a serial 
port for connection to the port 136 on the pay 
telephone. The serial port permits data transfer with 

55 the access circuit within the pay telephone and 
supplies operating power to the solenoid lock. 

The bar code label on each coin box contains, 
in scanner-readable bar code format, the informa- 

10 
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tion printed or written onto the collection stubs 
presently associated with coin boxes and manually 
filled in by the collectors. As known to those skilled 
in the art. this information includes an identification 
number of the individual receptacle, the telephone 
number of the pay phone for which the receptacle 
is intended, the route and stop numbers at which 
that telephone is located, the number of the full 
receptacle which a particular empty receptacle re- 
places, the time and date of collection, the iden- 
tification of the collector, and other information as 
required by the pay-telephone operator. The man- 
ual collection stubs presently in use also contain 
blocks manually checked by the collector when the 
coin box is overflowing or when larceny is indicated 
by- the. condition of the telephone. 

At the present time, some of the foregoing 
information is preprinted on the collection stubs 
and attached to each empty coin box. and the 
remaining information is manually entered by the 
collector when each full coin box is removed from 
a pay telephone. Those manual stubs are returned 
to the coin processing center along with the full 
coin boxes, where the manually-entered information 
must then be keyed into a computer for correlation 
with the coin boxes and the count of money con- 
tained in each box. By containing all the foregoing 
information on a bar code label affixed to each coin 
box, the collection process is significantly speeded 
and errors in manual entry of date and time in- 
formation by the collector are eliminated. 

Fig. 11 A illustrates operational steps associated 
with the bar-code identification of the coin boxes 
using the scanner 148 associated with the portable 
terminal 96 shown in Fig. 8 and the portable 
terminal135 shown in Fig. 10. It should be under- 
stood that the scanner 148 and associated scan- 
ning functions outlined in Fig. 11A are optional to 
the secured access system previously described 
with reference to Figs. 10 and 11. Likewise, the 
operational steps shown in Fig. 11A and associated 
with the bar code labeling system are in addition to 
the operational steps shown in Fig. 11 for obtaining 
access to the coin box within a particular pay 
telephone. 

Referring now to Fig. 11 A, the portable terminal 
is connected to or otherwise in data communication 
with a pay telephone and the PIN of the collector is 
entered as shown at 138 and 139. those steps 
previously described with respect to Figs. 9 and 
11. The collector then selects a empty coin box 
149 intended for the particular pay telephone and 
scans the label 150 on that coin box. using the 
scanner 148 associated with the portable terminal. 
This scanning step appears at 156 in Fig. 11 A and 
can take place after access is granted to the par- 
ticular pay telephone, so that the particular tele- 
phone number is associated in the memory of the 



portable terminal with the identification number ob- 
tained by scanning the label on the empty coin box 
149. The collector next uses the scanner 148 to 
scan the bar code label on the full coin box 131 

5 being removed from the pay telephone, as, shown 
at 157 in Fig. 11 A. The collector then places th 
empty coin box 149 in the receptacle of the pay 
telephone and closes the door 130 of the pay 
telephone, and if necessary selects certain 

70 preprogrammed special conditions from the appro- 
priate menu on the portable terminal. These special 
conditions, as indicated at step 158 in Fig. 11 A. 
include overflow of the coin box. indication of lar- 
ceny, or other service needs indicated by the col- 

75 lector's visual inspection of the pay telephone. This 

indication of ^special- conditions at 158 in Fig. 11A 

thus corresponds in function to the check boxes on 
the stubs now in use and manually filled in by the 
collectors. 

20 After entering any special conditions into the 

portable terminal, the collector disconnects that ter- 
minal from the pay telephone and travels to the 
next telephone scheduled for collection. The porta- 
ble terminal stores the coin box and telephone data 

25 obtained from each collection, and periodically up- 
loads that data through a modem 152 and dial-up 
telephone connection to a host computer 162 as 
indicated at 159 in Fig. 11 A. This host computer 
advantageously is connected to coin sorting and 

30 counting equipment 163 located at the coin pro- 
cessing center where the various full coin boxes 
131 removed from pay telephones are brought for 
emptying and costing. This coin sorting and count- 
ing equipment 163 is known to those skilled in the 

35 art, and preferably is equipped with a bar code 
scanner 164 for reading the bar code label on each 
coin box 131 as the contents of that coin box are 
emptied into the sorting and counting equipment. 
The coin count from each coin box thus becomes 

40 associated with that coin box and with the pay 
telephone from which that coin box was removed, 
as shown from information previously uploaded to 
the host computer 162 from the portable terminal, 
without manual entry of data by the collector in the 

45 field or by others at the coin processing center. 

It should also be understood that the foregoing 
relates only to a preferred embodiment of the 
present invention, and that numerous changes and 
modifications therein may be made without depart- 

50 ing from the spirit and scope of the invention as 
defined in the following claims. 

Claims 

55 1. A method for allowing a particular person to 
access a secured location, characterized by 
the steps of: 

generating encoded information identifying 
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an access code for a particular secured loca- 
tion and an identification number for a particu- 
lar person authorized to access that location; 

transferring the encoded information to the 
secured location; 5 

comparing the access code in the en- 
coded information with an access code pre- 
viously stored at the secured location to verify 
that a predetermined relation exists between 
the two access codes; and io 

allowing access to the secured location 
only if the verification is true. 

2. The method as in Claim 1. further character- 
ized by the step of: is 

comparing the identification number in the 
encoded information with a current identifica- 
tion number of the person seeking access to 
the secured location to verify that the current 
identification number is the same as the iden- 20 
tification number in the encoded information; 
and 

allowing access to the secured location 
only if both verifications are true. 

25 

3. The method as in Claim 2, wherein: 

the access code in the encoded informa- 
tion is a present access code; 

the encoded information also contains a 
new access code for the next authorized ac- 30 
cess to the secured location, and 

the step of comparing access codes in- 
cludes comparing the present access code in 
the encoded information with an access code 
previously stored at the secured location, and 35 
then 

in response to granting access, replacing 
the access code previously stored at the se- 
cured location with the new access code con- 
tained in the encoded information, so that the 40 
new access code becomes stored at the se- 
cured location for comparison with a subse- 
quent present access code the next time ac- 
cess to the particular secured location is 
sought. 45 

4. The method as in Claim 2, wherein: 

the step of transferring the encoded in- 
formation to the secured location comprises 
entering that encoded information into a porta- so 
ble terminal carried by the person seeking 
access to the secured location; and the meth- 
od is characterized by the further steps of 

entering the current identification number 
into the terminal; 55 

comparing the identification number in the 
encoded information with the identification 
number entered into the terminal; and 



erasing the encoded access message from 
the terminal if a predet rmined relation be- 
tween the identification numbers is not pre- 
sented by the comparison. 

5. The method as in Claim 4. characterized by 
the further steps of: 

transferring the access message in en- 
coded form from the terminal to the secured 
location, if and only if the predetermined rela- 
tion between identification numbers is present; 
and thereafter 

performing the step of comparing access 
codes. 

6. The method as in Claim 4, wherein: 

the step of generating encoded information 
is characterized by generating a signal contain- 
ing said encoded information; and the method 
is characterized by the further steps of: 

decoding the signal containing encoded 
access information after transferring that signal 
to the terminal; 

performing the step of comparing the Iden- 
tification numbers; and then 

reincoding the access information within 
the terminal if and only if the predetermined 
relation between identification numbers is 
present; and thereafter 

transferring the reincoded access informa- 
tion to the secured location. 

7. The method as in Claim 4, wherein: 

the portable terminal contains a unique 
serial number distinguishing that terminal from 
other terminals; 

the encoded information includes the serial 
number of a particular terminal authorized for 
the next access to the secured location; and 
the method is characterized by the further 
steps of 

comparing the serial number in the en- 
coded information with the serial number within 
the terminal to determine whether the serial 
numbers match; and 

aborting the access attempt if the terminal 
identification numbers do not match. 

8. The method as in Claim 2, further character- 
ized in that the secured location is a selected 
one of plural automated teller machines 
(ATMs), and comprising the steps of: 

generating the encoded access message 
containing information identifying an access 
code previously stored at the selected ATM, 
and a personal identification number (PIN) for 
the particular person; 

entering the encoded message in a termi- 
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nal apart from the ATM; 

entering the PIN in unencoded form in the 
portable terminal; 

comparing the entered PIN with the PIN 
contained in the encoded message previously 
entered into the portable terminal to authorize 
an access only if the PINs bear a predeter- 
mined relation to each other; and then 

establishing data communication between 
the portable terminal and an ATM, and trans- 
ferring the access message in encoded form 
from the portable terminal to the ATM; 

comparing the access code contained in 
the encoded message with the access code 
previously stored at the ATM to verify that the 

access-code- in. the encoded information Js the 

same as the access code previously stored at 
the ATM; 

re-entering the PIN In unencoded form into 
the portable terminal; 

. _comparingJhe_re-entered PIN_withJhe PIN 

contained in the encoded message commu- 
nicated to the ATM from the terminal; and 

granting access to the ATM only if the 
same access codes are present and the re- 
entered PIN bears a predetermined relation to 
the PIN in the encoded message communi- 
cated to the ATM. 

9. The method as in Claim 8. wherein: 

the portable terminal erases the PIN pre- 
viously entered in unencoded form, in re- 
sponse to the first step of comparing that PIN 
with the PIN in the encoded access message, 

so that the unencoded PIN cannot be de- 
termined thereafter by access to information 
entered in the portable terminal. 

10. The method as in Claim 8. wherein: 

the access code in the encoded access 
message is a present access code, and the 
encoded message also contains a future ac- 
cess code for the next authorized access to 
the ATM, and further characterized by the step 
of 

substituting the future access code for the 
access code previously stored at the selected 
ATM in response to granting access to the 
ATM, so that the future access code remains 
at the selected ATM for comparison with a 
present access code in another encoded mes- 
sage the next time access to the ATM is 
sought. 

11. The method as in Claim 10. comprising the 
further step of erasing both access codes from 
the portable terminal once the future access 
code is substituted for the previous access 



code. 

12. The method as in Claim 1, further character- 
ized by the steps of: 

5 generating encoded information including 

a unique access code previously stored at the 
secured location, and an identification number 
for the particular person; 

transferring the encoded information to the 
10 secured location; 

comparing the access code in the en- 
coded information with the access code pre- 
viously stored at the secured location to verify 
that a predetermined relation exists there- 
15 between; and 

aIlowing_access.-to the-secured location 

only if the verification is true. 

13. The method as in Claim 12, comprising the 
20 further step of: 

replacing_the access code stored at th 

secured location with a new access code in 
response to allowing access, so that the new 
access code is stored at the secured location 
25 for comparison when attempting the next ac- 

cess. 

14. The method as in Claim 12, wherein: 

the step of generating encoded information 
30 includes producing the new access code in 

encoded form so that the encoded new access 
code is included in the encoded information 
transferred to the secured location. 

35 15. Apparatus for obtaining selective access to a 
secured location, comprising: 

means associated with the secured loca- 
tion to receive and store an access code r - 
quired for the next access to the remote loca- 

40 tion; 

terminal means separate from the secured 
location for receiving an access message con- 
taining in encoded form an access code and a 
personal identification number (PIN) for a cer- 
45 tain person authorized to access the location; 

means associated with the terminal means 
for entering an unencoded PIN; 

means associated with the terminal means 
for producing a certain logic state when the 
60 entered PIN has a predetermined relation to 

the PIN encoded in the access message: 

data transfer means selectively operative 
to transfer the encoded access message to the 
secured location only in response to the cer- 
55 tain logic state; and 

means associated with the secured loca- 
tion for comparing the access code in the 
access message with an access code stored at 
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the secured location and providing an authori- 
zation signal allowing access to the secured 
location only in response to a predetermined 
relation between the access codes. 

6 

16. Apparatus as in Clainr^ 15, wherein: 

the terminal means is operative in re- 
sponse to the certain logic state to erase the 
unencoded PIN previously entered in the ter- 
minal means, whereby the terminal means io 
cannot transfer the unencoded PIN to the se- 
cured location. 

17. Apparatus as in Claim 15, wherein: 

the secured location includes means re- 75 
sponsive to re-entry of an unencoded PIN at 
the entry means of the terminal to compare the 
re-entered PIN with the PIN in the encoded 
access message transferred to the secured 
location and to provide the access authoriza- 20 
tion signal only in response to a predetermined 
relation between the PINs in addition to the 
predetermined relation between access codes. 

18. Apparatus as in Claim 15, wherein the secured 25 
location is a pay telephone having a receptacle 

for receiving a movable coin box and a door 
for preventing unauthorized access to the re- 
ceptacle, and further comprising: 

a latch associated with the door and oper- 30 
ative only in response to the authorization sig- 
nal to release the door for access to the recep- 
tacle. 

19. Apparatus as in Claim 18, and further compris- 35 
ing: 

an encoded label associated with each 
coin box to identify that coin box and selected 
information related to that coin box; and 

scanning means associated with the termi- 40 
nal means to scan the label on each full coin 
box removed from a pay telephone and on 
each empty coin box installed in the pay tele- 
phone, whereby signals identifying the full and 
empty coin boxes are stored in the terminal. 45 

20. Apparatus as in Claim 18. wherein: 

the latch comprises a solenoid selectively 
operative to release the door; and 

circuit means connected to a telephone so 
line for the pay telephone and operative in 
response to the authorization signal to tem- 
porarily supply the solenoid with ringing cur- 
rent on the telephone line, 

whereby the solenoid operates to unlatch 55 
the door in response to ringing current on the 
telephone line during the temporary connec- 
tion. 



21. Apparatus as in Claim 18, wherein: 

the latch comprises a solenoid selectively 
operative to release the door; and further com- 
prising 

means selectively operative in response to 
the authorization signal to supply operating 
current to the solenoid from the terminal 
means, 

whereby the solenoid releases the door. 
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0 A system for authorizing access to a secured 
location, such as the vault of an automated teller 
machine (ATM) or the corn box of a pay telephone, 
without a key or combination for the secured loca- 
tion, and without requiring a fixed communication 
link extending to the location. A service technician 
receives a encoded access message which identifies 
a present access code previously stored at the se- 
cured location, the personal identification number 
(PIN) of the technician, and the identification number 
of a portable terminal assigned to that technician. 
The technician manually enters the encoded access 
message and the proper PIN into the terminal, where 
the identification number stored in the terminal and 
the manually-entered PIN are verified against the 
information encoded in the access message. If that 
information is authenticated, the technician then pro- 
ceeds to the secured location and connects the 
portable terminal to a processor at that location. The 
encoded access message is transferred from the 
terminal to the secured location, where the access 
code previously stored at that location is compared 
with information contained in the encoded access 
message. The technician must also re-enter the 
proper PIN at this time. Access is granted only if all 
information is verified by information in the encoded 



access message, if access is allowed, the access 
code at the secured location is replaced by a new 
access code contained in the encoded access mes- 
sage, and that new access code is stored for the 
next authorized access to the particular secured 
location. 
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